Description
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Published: 2026-09-30
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

NVIDIA GPU Display Driver for Windows and Linux contains a kernel‑mode out‑of‑bounds write vulnerability as described in CWE‑787. An attacker who can trigger this flaw may overwrite memory outside the intended bounds, leading to code execution, privilege escalation, denial of service, information disclosure, or data tampering.

Affected Systems

The flaw impacts NVIDIA GPU products including GeForce, RTX, Quadro, NVS, Tesla, and the Virtual GPU Manager across both Windows and Linux operating systems. No specific driver version ranges are listed, so any installation of the affected driver family is potentially vulnerable.

Risk and Exploitability

The CVSS base score of 7.8 indicates high severity, and although an EPSS score is not provided, the lack of a readily available mitigation suggests risk remains. The flaw exists in the kernel component, implying that exploitation likely requires local privileges or the ability to send crafted data to the driver, such as through a malicious application or firmware. If an attacker gains enough access to the GPU interface, they could execute arbitrary code with kernel privileges.

Generated by OpenCVE AI on September 30, 2026 at 19:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update all NVIDIA GPU drivers to the latest official release that contains the CVE‑2026‑47548 fix.
  • Verify that the updated drivers are digitally signed by NVIDIA and have not been tampered with during installation.
  • If an immediate driver update is unavailable, isolate or remove NVIDIA GPU drivers from non‑essential systems and disable GPU acceleration for critical workloads until a patched driver is deployed.

Generated by OpenCVE AI on September 30, 2026 at 19:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Title Kernel-Mode Out-of-Bounds Write in NVIDIA GPU Display Driver

Wed, 30 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-09-30T17:59:51.801Z

Reserved: 2026-05-19T19:55:44.855Z

Link: CVE-2026-47548

cve-icon Vulnrichment

Updated: 2026-09-30T17:57:27.648Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T16:17:22.600

Modified: 2026-09-30T18:18:27.337

Link: CVE-2026-47548

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T19:00:14Z

Weaknesses